Security
Two-factor authentication on your Axos workspace
TOTP-based second factor layered on top of the magic-link sign-in. Compatible with every RFC 6238 authenticator.
How it works
- Tap the magic link as usual.
- Instead of landing on
/workspace, you land on a TOTP prompt. - Enter the 6-digit code from your authenticator app.
- The workspace opens. The
ax_wscookie is set as usual, valid 90 days.
2FA only kicks in on new sign-ins. Existing browsers with a valid ax_ws cookie continue to open the workspace directly.
Supported apps
- Google Authenticator (Android / iOS)
- Aegis (Android)
- Raivo (iOS)
- 1Password (any platform)
- Bitwarden (any platform)
- Yubico Authenticator (any platform)
- Microsoft Authenticator (Android / iOS)
Any authenticator that implements RFC 6238 with SHA-1 and 30-second time step is compatible.
Backup codes
When you turn 2FA on, eight one-time backup codes are generated. Store them in a password manager, a paper envelope in a safe, or both — never in the workspace itself.
AXBK-4T3H-92QW AXBK-M8LR-1KDP AXBK-77XZ-6VYA AXBK-9GH2-BC4E AXBK-K8LM-N3PQ AXBK-R7ST-U2VW AXBK-X1YZ-A5BC AXBK-D9EF-G4HI
Codes are examples. Yours are generated on enrolment.
Turn 2FA on now
Signed in? Open /account → Security → Enable 2FA. Scan the QR code with your authenticator, enter one code to confirm, download the backup codes.
Lost the 2FA device? See the recovery guide.